Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.7213

Added to the Dr.Web virus database: 2024-04-20

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • fe8lrlnbjsm2
Kills system processes:
  • sshd
Kills the following processes:
  • systemd
  • systemd-journal
  • systemd-udevd
  • systemd-timesyn
  • cron
  • dbus-daemon
  • rsyslogd
  • systemd-logind
  • agetty
  • (sd-pam)
  • dhclient
  • run.sh
  • apt-helper
  • (ogrotate)
  • install
  • tmux: client
  • dash
  • sleep
  • hostname
  • fe8lrlnbjsm2
  • udevadm
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:8345
Establishes connection:
  • 8.#.8.8:53
  • 8.#.4.4:53
  • 21#.##.149.14:35342
  • 13#.#95.4.2:53
  • 51.##.149.139:53
  • 1.#.1.1:53
  • 81.###.136.222:53
Sends data to the following servers:
  • 41.##.4.53:37215
  • 41.##.226.22:37215
  • 15#.###.205.19:37215
  • 19#.###.103.81:37215
  • 19#.##.20.217:37215
  • 41.###.143.224:37215
  • 41.##.120.142:37215
  • 19#.###.12.154:37215
  • 41.###.74.250:37215
  • 19#.###.17.249:37215
  • 19#.###.75.209:37215
  • 19#.##8.6.230:37215
  • 13#.##.15.142:37215
  • 15#.###.248.195:37215
  • 19#.##3.2.128:37215
  • 19#.###.41.169:37215
  • 19#.###.73.158:37215
  • 15#.##.23.218:37215
  • 15#.###.160.26:37215
  • 14#.###.39.157:37215
  • 16#.##.165.224:37215
  • 15#.###.254.89:37215
  • 87.##.253.249:37215
  • 19#.##0.7.27:37215
  • 15#.##.201.87:37215
  • 19#.##.106.161:37215
  • 11#.###.201.60:37215
  • 19#.##.51.97:37215
  • 19#.###.147.180:37215
  • 41.##.134.184:37215
  • 41.##.51.199:37215
  • 20.###.16.113:37215
  • 10#.##.10.166:37215
  • 41.##.253.26:37215
  • 15#.###.222.216:37215
  • 41.###.141.237:37215
  • 19#.##3.85.83:37215
  • 19#.###.147.88:37215
  • 15#.###.72.104:37215
  • 14#.##4.163.1:37215
  • 16#.###.91.210:37215
  • 19#.##.230.145:37215
  • 15#.##6.0.209:37215
  • 15#.###.99.125:37215
  • 75.##.210.123:37215
  • 19#.###.243.90:37215
  • 41.##.148.241:37215
  • 19#.##.25.231:37215
  • 15#.##.145.23:37215
  • 19#.##.38.64:37215
  • 19#.##.73.86:37215
  • 19#.#.249.224:37215
  • 41.###.178.70:37215
  • 15#.###.164.78:37215
  • 41.###.99.148:37215
  • 41.##.131.156:37215
  • 41.###.56.46:37215
  • 41.###.133.153:37215
  • 60.###.81.49:37215
  • 41.###.230.214:37215
  • 41.###.49.194:37215
  • 41.###.89.240:37215
  • 53.###.5.139:37215
  • 15#.###.254.26:37215
  • 19#.##.60.169:37215
  • 41.##.10.93:37215
  • 21#.###.143.46:37215
  • 15#.##.54.126:37215
  • 41.##.121.49:37215
  • 19#.###.219.201:37215
  • 41.###.87.75:37215
  • 41.###.126.139:37215
  • 41.##.88.154:37215
  • 41.###.45.118:37215
  • 19#.###.132.68:37215
  • 41.###.11.64:37215
  • 41.##.156.140:37215
  • 15#.###.48.157:37215
  • 19#.###.95.162:37215
  • 15#.###.187.82:37215
  • 19#.#.233.170:37215
  • 19#.##.22.224:37215
  • 15#.###.204.85:37215
  • 41.###.185.49:37215
  • 41.###.80.176:37215
  • 15#.##.22.46:37215
  • 19#.###.11.249:37215
  • 41.###.252.226:37215
  • 19#.###.230.243:37215
  • 41.###.162.125:37215
  • 15#.###.62.206:37215
  • 15#.###.98.181:37215
  • 19#.###.10.246:37215
  • 41.###.55.53:37215
  • 41.###.80.127:37215
  • 11#.##.110.43:37215
  • 41.###.250.157:37215
  • 15#.##5.40.47:37215
  • 15#.##.140.30:37215
  • 19#.#.210.0:37215
  • 19#.###.63.145:37215
  • 41.##.228.116:37215
  • 32.###.201.35:37215
  • 19#.###.253.65:37215
  • 14#.###.156.33:37215
  • 41.###.177.92:37215
  • 19#.###.169.54:37215
  • 19#.###.217.49:37215
  • 13#.###.194.43:37215
  • 15#.###.142.95:37215
  • 41.###.219.98:37215
  • 19#.###.138.219:37215
  • 19#.##7.2.243:37215
  • 99.###.8.211:37215
  • 15#.##4.227.3:37215
  • 41.###.137.56:37215
  • 19#.##.87.61:37215
  • 15#.##.84.49:37215
  • 18#.###.166.94:37215
  • 19#.##.93.126:37215
  • 12#.##.189.83:37215
  • 41.###.49.88:37215
  • 22#.##.140.66:37215
  • 41.##.82.202:37215
  • 19#.##.63.194:37215
  • 15#.###.81.187:37215
  • 41.##.166.157:37215
  • 18#.###.131.71:37215
  • 41.###.46.30:37215
  • 15#.##.204.151:37215
  • 19#.##.88.26:37215
  • 82.###.150.62:37215
  • 41.##.40.57:37215
  • 41.##.162.151:37215
  • 19#.###.88.130:37215
  • 19#.###.194.46:37215
  • 19#.##8.58.99:37215
  • 41.##.119.140:37215
  • 15#.###.184.187:37215
  • 80.###.119.245:37215
  • 41.###.215.0:37215
  • 15#.##.229.205:37215
  • 15#.##1.92.61:37215
  • 15#.###.79.227:37215
  • 19#.###.123.166:37215
  • 15#.##.245.59:37215
  • 15#.###.222.163:37215
  • 71.###.56.67:37215
  • 19#.##7.40.72:37215
  • 41.###.42.132:37215
  • 15#.##.219.240:37215
  • 15#.##.147.197:37215
  • 19#.##.191.189:37215
  • 20.##.37.190:37215
  • 41.###.255.247:37215
  • 20#.###.234.56:37215
  • 15#.###.40.251:37215
  • 17#.##.226.246:37215
  • 19#.###.213.192:37215
  • 10#.##.183.70:37215
  • 41.###.242.91:37215
  • 41.##.117.215:37215
  • 15#.##.130.153:37215
  • 15#.###.99.140:37215
  • 19#.###.101.190:37215
  • 16#.###.196.97:37215
  • 19#.###.128.117:37215
  • 41.###.103.110:37215
  • 20#.###.148.228:37215
  • 15#.###.91.155:37215
  • 15#.##.36.45:37215
  • 15#.###.90.241:37215
  • 41.##.67.108:37215
  • 15#.###.175.35:37215
  • 41.###.43.49:37215
  • 15#.###.157.189:37215
  • 15#.##.150.202:37215
  • 22#.##4.15.52:37215
  • 41.###.202.249:37215
  • 41.##.36.163:37215
  • 15#.##.88.32:37215
  • 23.##.133.113:37215
  • 15#.###.88.148:37215
  • 15#.###.115.208:37215
  • 19#.###.135.247:37215
  • 75.##.23.67:37215
  • 19#.###.238.244:37215
  • 15#.##.175.149:37215
  • 19#.##.126.160:37215
  • 15#.##0.99.63:37215
  • 13#.###.92.109:37215
  • 41.###.27.210:37215
  • 19#.###.96.120:37215
  • 41.###.90.61:37215
  • 41.##.46.45:37215
  • 41.##.20.191:37215
  • 17#.###.225.251:37215
  • 15#.##7.253.1:37215
  • 19#.##.199.157:37215
  • 19#.###.245.159:37215
  • 53.###.91.17:37215
  • 19#.##.66.71:37215
  • 15#.###.63.213:37215
  • 15#.##3.75.83:37215
  • 41.###.50.153:37215
  • 15#.##.132.170:37215
  • 41.###.44.31:37215
  • 15#.##.186.122:37215
  • 19#.##.158.101:37215
  • 15#.###.155.153:37215
  • 15#.###.44.150:37215
  • 19#.##.2.22:37215
  • 15#.##7.139.1:37215
  • 16#.###.223.140:37215
  • 41.###.105.149:37215
  • 15#.###.172.252:37215
  • 13#.##3.35.51:37215
  • 41.##.64.27:37215
  • 19#.##.115.208:37215
  • 15#.###.111.123:37215
  • 14#.##.24.45:37215
  • 15#.##.251.138:37215
  • 21#.###.166.102:37215
  • 14#.##.99.40:37215
  • 41.##.208.58:37215
  • 41.###.5.188:37215
  • 19#.##2.15.73:37215
  • 19#.###.52.121:37215
  • 5.###.190.107:37215
  • 10#.###.76.102:37215
  • 41.###.129.242:37215
  • 86.###.245.37:37215
  • 41.###.99.155:37215
  • 19#.##.79.157:37215
  • 41.###.164.149:37215
  • 19#.##9.74.32:37215
  • 15#.###.91.236:37215
  • 15#.###.115.147:37215
  • 41.###.157.13:37215
  • 41.###.184.38:37215
  • 10#.##2.44.34:37215
  • 15#.###.113.54:37215
  • 41.##.229.150:37215
  • 41.##.236.222:37215
  • 19#.##.62.11:37215
  • 15#.###.124.87:37215
  • 41.#.#78.254:37215
  • 15#.###.114.39:37215
  • 15#.##3.116.4:37215
  • 41.###.40.24:37215
  • 18#.##.127.194:37215
  • 19#.##.5.127:37215
  • 87.##.19.245:37215
  • 41.##.138.1:37215
  • 19#.##.196.148:37215
  • 19#.###.206.234:37215
  • 0.0.0.0

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number